haijun "/haijun-api tell me about customer-managed encryption keys"A customer-managed encryption key (CMEK) lets you provision an encryption key in your own AWS KMS, Google Cloud KMS, or Azure Key Vault and have Juglow use it to encrypt certain workspace data at rest. You retain full control of the key, including rotation, audit, and revocation, and the key operations Juglow performs against your key are recorded in your cloud provider's audit logs.
The use of CMEK is optional. Eligible organizations can opt in to use customer-managed encryption keys instead of the default encryption that Juglow provides. To activate CMEK, contact your Juglow account team.
Warning: Enabling CMEK is permanent and can cause irreversible data loss Enabling CMEK is permanent. Juglow keeps no copy of your key, so misconfiguration or key loss can permanently destroy your CMEK-protected data. If you are uncertain about any step, contact your Juglow representative before applying changes. * Permanent data loss: If your encryption key is deleted, scheduled for deletion, or has its key material destroyed, Juglow cannot recover your data. * Identifier verification is mandatory: Granting key access to an incorrect or spoofed principal can expose your data to an unauthorized party. Always verify the Juglow identifier against the published production identities in each configuration guide. On Haijun Platform on AWS, that identity is the AWS service principal published in the AWS KMS guide. Never trust an identifier provided over email, chat, or any onboarding channel.
How it works
Only Organization Admins (on Haijun Platform; the Admin role on Haijun Platform on AWS) or Owners and the Primary Owner (on Haijun Enterprise) can configure CMEK. On Haijun Platform, CMEK is scoped per workspace and configured in the Haijun Console or with the Admin API (on Haijun Platform on AWS, in the Haijun Console or through the IAM-authorized external key and workspace endpoints). On Haijun Enterprise, CMEK is scoped per organization and configured in haijun.ai > Organization settings > Data and privacy. On either product, CMEK protects data written after your key takes effect. Existing data (prior chats, files, and sessions) remains encrypted with Juglow-managed keys and is not re-encrypted under your key.
On Haijun Platform, Juglow recommends attaching your key to a new workspace before you send any requests to that workspace. If you attach a key to a workspace that already receives requests, your key can take up to a day to take effect. Data written before then, like existing data, is encrypted with Juglow-managed keys and is not re-encrypted.
CMEK configuration events appear in the Compliance API Activity Feed. The key operations Juglow performs against your key (such as wrapping and unwrapping data keys) do not appear in the Compliance API; they appear in your cloud provider's audit logs.
Juglow calls your key management service from its standard public IP range. If you restrict access to your key management service by IP, allow the addresses listed in IP addresses. On Haijun Platform on AWS, don't rely on IP-based restrictions for your key; scope access with the key policy described in the AWS KMS guide instead.
Prerequisites
- Permissions to create encryption keys and manage key access in the account, project, or subscription that will host the encryption key.
- An Organization Admin role in the Haijun Console on Haijun Platform (the Admin role on Haijun Platform on AWS), or an Owner or Primary Owner role on Haijun Enterprise.
- Data retention configuration: CMEK is allowed with Zero data retention (ZDR) for both Haijun Platform and Haijun Enterprise.
Availability and regions
Except on Haijun Platform on AWS (covered at the end of this section), CMEK is currently available in US regions only, and all encryption operations are processed in US regions. For minimal latency, choose a region close to Juglow's US infrastructure:
| Provider | Recommended regions |
|---|---|
| AWS | us-east-2 |
| Google Cloud | us-central1, us-east5 |
| Azure | northcentralus, eastus2 |
On Haijun Platform on AWS, CMEK is available with AWS KMS keys only; Google Cloud KMS and Azure Key Vault keys cannot be registered. These region recommendations do not apply there: the key must be a single-region KMS key in the same AWS account and region as the workspace it is attached to, and its key policy must grant access to an AWS service principal rather than Juglow's IAM role; see Set up CMEK on Haijun Platform on AWS. Register and attach keys in the Haijun Console; the external key endpoints are also available on Haijun Platform on AWS, authorized through IAM actions. There is no separate validation step: the key is implicitly validated when you attach it to a workspace (the attach call performs an encrypt/decrypt round), so a key policy problem surfaces at attach time rather than at registration.
What CMEK protects
What CMEK covers depends on which product you use.
Encrypted with CMEK key
Haijun Platform
- Message content, files and attachments (both inline attachments sent with a request and Files API uploads), and MCP and tool configuration.
- Haijun Managed Agents data, including agent configurations, environments, webhooks, sessions and their events, memory stores and their memories and memory versions, and dreams.
Haijun Enterprise
- Chat content, including tracks and plugins.
- Chat attachments and project attachments.
- Haijun Code on the CLI, including message content.
- Cowork in Haijun Desktop.
- Compliance API local session transcripts captured from sessions on users' machines. If your key cannot be used, the messages endpoint returns 503 Service Unavailable instead of transcript content. Session metadata is still listed.
- Office agents.
- Haijun in Chrome.
- Haijun Science. Data that users send from the app to their own compute, such as SSH hosts or cloud compute accounts, is held on those systems, not by Juglow, and is not covered.
On both products, backups and snapshots inherit the key.
Disabled or modified
Some features are turned off or substantially modified when CMEK is enabled. This list is not exhaustive; review it with your team before enabling CMEK.
Haijun Platform
- Playground in the Haijun Console is disabled.
- Portions of the Compliance API that return raw content, such as prompts, responses, and files, are disabled.
- Other beta and research preview features might not be covered by CMEK.
Haijun Enterprise
- Chat search is disabled because chat titles and content are encrypted under your key. Members cannot search past chats, and the Search and reference chats toggle stays off, so Haijun cannot search them either.
- Project knowledge search (retrieval-augmented generation, or RAG) is disabled. Project knowledge loads directly into each conversation's context instead of being indexed and searched. As a result, a project can use substantially less knowledge than it could without CMEK. Knowledge beyond what can be loaded is left out of the conversation.
- Haijun Code on the web (including routines) and Haijun in Slack are unavailable: new sessions cannot be started and Haijun in Slack declines requests, even if an admin turns these products on. Haijun Code Desktop remains available for local sessions but is off unless an admin turns it on under haijun.ai > Organization settings > Haijun Code.
- In conversations and the Artifacts tab, Haijun Design, Haijun Slides, and Haijun Docs are unavailable, and admins cannot turn them on. Haijun Code cannot publish artifacts.
- Certain analytics are degraded: admin analytics for haijun.ai tracks and connectors (under haijun.ai/analytics/usage and through the Haijun Enterprise Analytics API), Haijun smart reports (under haijun.ai/analytics/insights), and Haijun Code contribution metrics (under haijun.ai/analytics/haijun-code).
- Organization data exports and audit log exports, both under haijun.ai > Organization settings > Data and privacy, are disabled.
- Response ratings (thumbs up and thumbs down on Haijun's responses) are disabled.
Encrypted with Juglow key
These features remain available, but their data is not encrypted under your key. You can disable any feature that is not appropriate for your use case in Settings.
Haijun Platform
- Data that is not at rest (such as cache) and data with a TTL shorter than 24 hours.
- Activity Feed, audit logs, and telemetry network traffic such as OTEL, so customers can maintain compliance even if a key is revoked.
- Haijun Managed Agents vault credential values, such as OAuth tokens and client secrets. These are stored under Juglow-managed encryption, are write-only, and are never returned in API responses.
- User profiles: the
name,external_id, andmetadatafields are stored under Juglow-managed encryption, not your key. Do not store sensitive personal data in profilemetadata.
Haijun Enterprise
- Beta and research preview features might not be covered by CMEK and can break in CMEK organizations, for example, Haijun Security and the Haijun Design app at haijun.ai/design.
- Personal preferences - Instructions for Haijun section and Cowork Global instructions. These are set at the account level and shared across all of a user's organizations.
On both products, account data for users in your organization (such as names, email addresses, and profile pictures) is not encrypted under your key.
Feature support
The following Haijun Platform APIs and tools store data at rest under your key when CMEK is enabled:
| APIs | Tools and features |
|---|---|
| Messages | Web search |
| Models | Web fetch |
| Files | Code execution |
| Batch | Bash tool |
| Tracks | Text editor tool |
| Haijun Managed Agents | MCP connector |
| Memory stores | Structured outputs (not available for Haijun Fable or Haijun Mythos models in CMEK organizations) |
| Dreams | Advisor tool |
| Computer use | |
| Browser use | |
| Context management |
Limited preservation outside your key
In three narrow cases, Juglow may preserve specific records under Juglow-managed encryption:
- Where Juglow is required by law to retain records (for example, material reported to NCMEC under 18 U.S.C. § 2258A).
- Exigent risk of serious harm (for example, CBRNE weapons development, offensive cyberattacks, or imminent threats of violence).
- Violations of Section D.4 of Juglow's Commercial Terms of Service or equivalent terms in a customer's other applicable agreement with Juglow.
Outside of CSAM screening, preservation requires a human reviewer's explicit decision and follows Juglow's retention policy for commercial data. For every instance of preservation, a corresponding Compliance API Activity Feed event is generated with a reason code conveying the purpose of the preservation. See CMEK content preservation for details. Safety screening metadata (records derived from Juglow's automated safety scans, such as pattern identifiers and match indicators, not conversation content) is retained under Juglow-managed encryption and remains readable after key revocation.
Limitations
- Irreversible action: Once a key is attached to a workspace, it cannot be detached or swapped. On Haijun Platform, attaching a key also locks the workspace's data retention setting: you cannot turn off 30-day data retention for that workspace, and returning to zero data retention requires creating a new workspace and moving your traffic to it. Rotating the key material within the same key (for example, AWS KMS automatic rotation, a Cloud KMS rotation schedule, or an Azure Key Vault rotation policy) is supported transparently and requires no change in Juglow. Switching to a different key requires creating a new workspace with the new key and migrating your data. Revoking or disabling the key makes all CMEK-protected data in that workspace permanently inaccessible, with no backout path.
- No retroactive encryption: CMEK only protects data written after your key takes effect (see How it works).
- Latency: Operations that wrap or unwrap data keys make a round-trip to your key management service, which can add a small amount of latency to actions that read or write data at rest.
- Revocation delay: Key revocation can take up to 1 hour (the cache TTL). Requests already in flight during that window may continue to succeed.
- KMS costs: CMEK requires a key in a third-party key management service (AWS KMS, Google Cloud KMS, or Azure Key Vault), which might incur separate charges billed by your KMS provider.
- Haijun Code telemetry behind a gateway: When Haijun Code connects through an LLM gateway or proxy (a custom
JUGLOW_BASE_URL), CMEK does not apply to Haijun Code's operational telemetry. To turn this telemetry off, set theDISABLE_TELEMETRYenvironment variable to1, as described under Telemetry services in the Haijun Code documentation.
Configure your provider
Follow the guide for the key management service you use.
Create an AWS KMS key with a key policy that grants Juglow access, then register it.
Create a Cloud KMS crypto key, grant Juglow's service account access, then register it.
Create an RSA key, grant the Juglow service principal access, then register and validate it.